Skip to content

21 August 2026 | 8 min

CO2 Certificates Under Pressure: Why Climate Projects Are Now a GRC Topic

Handelsblatt is currently reporting that the German Environment Agency has declared CO2 certificates from 30 Chinese projects invalid. According to the report, the projects either overstated their climate impact or did not exist at all. One of the affected projects was reportedly financed by a Belgian subsidiary of ExxonMobil and promised savings of almost 96,000 tonnes of CO2. In total, the cancelled projects are said to have claimed CO2 savings of 2.1 million tonnes.

The case highlights a problem that reaches far beyond the oil and gas sector: climate claims are only as reliable as the governance behind them. Companies that use CO2 certificates, communicate climate neutrality or support ESG targets with external projects carry significant risk. If certificates are later deemed invalid, overstated or insufficiently evidenced, this is not only a sustainability problem. It becomes a compliance, reputation and control issue.

For GRC leaders, the message is clear: ESG claims need more than good intentions and external certificates. They need auditable processes, clear responsibilities, reliable data and robust evidence.

CO2 certificates and climate projects are coming under increasing scrutiny. The current Handelsblatt report shows that even large companies and formally reviewed projects are not automatically protected from later invalidation or doubt.

For companies, this means that anyone using climate projects must understand, review and document the underlying evidence. It is not enough to buy certificates and include their claimed impact in ESG communication, sustainability reporting or regulatory fulfilment without further scrutiny.

The topic is especially relevant for companies with net-zero targets, climate neutrality claims, CSRD or ESRS reporting, supplier assessments or carbon offsetting strategies. External ESG evidence must be treated like any other third-party risk: with due diligence, controls, monitoring and clear evidence.

Why CO2 Certificates Become a GRC Risk

CO2 certificates are intended to help companies offset emissions or meet regulatory requirements. In practice, however, the chain behind a certificate is complex. A single certificate may involve project developers, local operators, validators, verifiers, registries, brokers, buyers and several intermediaries.

This complexity creates risk. Companies often rely on the assumption that a certificate has already been sufficiently reviewed. But if doubts later arise about the existence, impact, additionality, calculation or documentation of a project, the risk remains with the company that relied on the certificate.

This is not only a legal issue. It is also a trust issue. Customers, investors, regulators, media and business partners increasingly expect climate-related claims to be reliable. Any company that advertises CO2 reductions or includes certificates in sustainability reporting must be able to explain why these claims are credible.

Carbon accounting therefore becomes a GRC topic. The decisive question is not only how much CO2 is claimed, but how that figure was calculated, reviewed, accepted and monitored.

The UER Case: When External Evidence Is Not Enough

In Germany, so-called Upstream Emission Reductions, or UERs, play a specific role. UER projects are measures designed to reduce CO2 emissions in the upstream part of oil and gas production, before crude oil is processed in a refinery. For the mineral oil industry, such projects were a way to meet greenhouse gas reduction quota requirements.

The current Handelsblatt report makes the issue tangible. If projects are later classified as suspicious or invalid, gaps emerge. Companies that used such certificates may need to close those gaps in other ways. But the more fundamental issue is governance: How did the company ensure that the project was reliable? Which checks were performed? Which warning signals existed? What role did external auditors or validators play? And how was the decision documented internally?

These are classic GRC questions. They show that ESG compliance is not just about reporting obligations. It requires robust decision-making processes.

ESG Claims Need the Same Discipline as Financial Controls

Many companies have published ESG targets, climate strategies and compensation measures in recent years. CO2 certificates were often seen as a pragmatic way to address emissions that are hard to avoid.

But the market is changing. Climate-related statements are being examined more critically. Greenwashing risks are increasing. CSRD and ESRS raise expectations for data quality, traceability and controls. Voluntary climate neutrality claims are also under greater public and regulatory scrutiny.

The consequence is clear: ESG claims need the same process discipline as financial figures or regulatory risk data. Companies must know where data comes from, who reviewed it, which assumptions were used, which controls exist and which evidence supports the claim.

A CO2 certificate is therefore not just a document. It is a data point, a third-party statement and a potential risk object.

Third-Party Risk in the ESG Context

The case shows why ESG and vendor risk are moving closer together. Climate projects are rarely managed fully in-house. Companies rely on project developers, intermediaries, certifiers, auditors, registries and local operators.

Each of these parties can introduce risk. Project documentation may be incomplete. Climate impact may be calculated incorrectly. Verification reports may have methodological weaknesses. Local controls may be insufficient. Conflicts of interest may remain unnoticed. Or a project may formally exist but fail to deliver the promised impact.

For GRC teams, this means that external ESG evidence belongs in third-party risk management. Companies need clear criteria for when a certificate can be accepted, what minimum information must be available, which providers and standards are approved and when additional review is required.

Companies that rely heavily on climate projects should not only purchase ESG evidence. They should monitor it.

What Companies Should Review Now

The Handelsblatt case is a useful trigger to review internal carbon credit governance. Companies should first understand whether and where CO2 certificates, offsets or external climate projects are used in their ESG strategy.

The next question is how robust the evidence behind these instruments is. Is there project-specific documentation? Are the project developer, certifier and registry known? Has the plausibility of the climate impact been assessed? Are there risks related to the project country, methodology, verification body or potential conflicts of interest? Were certificates simply purchased, or were they internally assessed and approved?

It is equally important to understand where certificates are used. Evidence that remains internal carries a different risk profile from evidence used in public sustainability claims, CSRD reporting, customer proposals or regulatory fulfilment mechanisms.

The more visible and material a climate claim is, the more mature the governance behind it must be.

Why Excel and Certificate Folders Are Not Enough

Many companies still manage ESG evidence in Excel files, SharePoint folders, email approvals or isolated sustainability tools. This may work for simple data points. But for CO2 certificates and climate projects, it is often not sufficient.

The challenge lies in the connections. A certificate belongs to a project. The project has a methodology, an operator, a country, a verification body, a lifecycle and specific assumptions about emission reductions. The certificate may be linked to an ESG target, a report, a claim or a regulatory obligation. At the same time, later findings, media reports, authority decisions or registry changes may alter the risk assessment.

If this information is stored separately, the audit trail is missing. In a critical situation, it becomes unclear who approved the certificate, on what basis the decision was made and whether new risks were considered in time.

Conclusion: Climate Claims Need Auditable Governance

The current Handelsblatt report on invalid CO2 certificates shows how quickly climate projects can move from a sustainability topic to a GRC risk. When certificates are later cancelled or projects are classified as questionable, the impact goes beyond the climate balance. It affects compliance, reputation, supplier governance, reporting and management responsibility.

For GRC leaders, the message is clear: ESG claims must be auditable. External certificates do not replace internal governance. Companies need clear processes, risk-based due diligence, documented approvals, ongoing monitoring and reliable evidence.

Zazoon supports companies in structuring carbon credit governance. This ensures that climate projects are not only purchased, but controlled, documented and managed in an audit-ready way.

FAQ

What is the current trigger?

Handelsblatt reports that the German Environment Agency has declared CO2 certificates from 30 Chinese projects invalid. According to the report, one of the affected projects was financed by a Belgian subsidiary of ExxonMobil.

Why is this a GRC topic?

Because CO2 certificates are not only sustainability instruments. If their impact cannot be reliably proven, they can trigger compliance, reputation, financial and regulatory risks.

What are UER projects?

UER stands for Upstream Emission Reductions. These are projects designed to reduce emissions in the upstream part of oil and gas production. In Germany, such evidence could be used to meet greenhouse gas reduction quota requirements.

Which companies are affected?

Companies that use CO2 certificates or external climate projects are directly affected. The topic is also relevant for any company communicating climate neutrality, net zero, ESG targets or CO2 reductions.

Is an external certificate sufficient evidence?

A certificate is an important document, but it does not replace internal governance. Companies should review the project information, verification reports, provider information and controls behind the certificate.

What should companies do now?

They should inventory their use of CO2 certificates, assess risks, review third parties, document approvals and establish ongoing monitoring.

How does Zazoon support this?

Zazoon helps companies centrally manage ESG requirements, climate projects, third parties, risks, controls, actions and evidence. This makes carbon credits and ESG claims traceable, controllable and audit-ready.

Related posts